| Precedente :: Successivo | 
	
	
		| Autore | Messaggio | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 28 Nov 2007 11:39    Oggetto: rAV mON LOG ---- AIUTATEMI |   |  
				| 
 |  
				| VI CHIEDO AIUTO .. PER FAVORE HO 3 PC IMPAZZITI
 MI DITE PERFAVORE IN MODALITAà PROVVISORIA QUALE DI QUESTI DEVO fIXARE ...
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 
 
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
 C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\WINDOWS\system32\cisvc.exe
 C:\WINDOWS\system32\inetsrv\inetinfo.exe
 C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 C:\WINDOWS\System32\snmp.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\mqsvc.exe
 C:\WINDOWS\system32\mqtgsvc.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
 C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
 C:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
 F:\RavMonE.exe
 C:\WINDOWS\System32\wbem\wmiapsrv.exe
 F:\RavMonE.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Kromix\Desktop\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar3.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [MOD] C:\Programmi\Microangelo\muamgr.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\wianmpa.exe
 O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe"
 O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\RavMonE.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &eBay Search - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O17 - HKLM\System\CS1\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
 O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LVCOMSer - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
 O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\SrvLnch\SrvLnch.exe
 O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: wampapache - Apache Software Foundation - c:\wamp\Apache2\bin\Apache.exe
 O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
 O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programmi\Windows Live\installer\WLSetupSvc.exe
 
 --
 End of file - 7522 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 28 Nov 2007 13:48    Oggetto: |   |  
				| 
 |  
				| Ciao kromixcts   Guarda questa discussione, scarica SmithFraudfix e fai la scansione del PC e posta quì il risultato con un altro log di HJT.
 Però al log di HJT non "tagliargli la testa" perchè ci permette di vederne la versione e il sistema operativo che utilizzi.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 28 Nov 2007 17:37    Oggetto: ecco fatto con smitfraundfix |   |  
				| 
 |  
				| Ti ringrazio anticipatamente della tua disponibilità e cortesia ecco qua:
 
 
 SmitFraudFix v2.256
 
 Scan done at 16.35.05,67, 28/11/2007
 Run from C:\Documents and Settings\Kromix\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Versione 5.1.2600] - Windows_NT
 The filesystem type is NTFS
 Fix run in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Process
 
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Programmi\Java\jre1.5.0_09\bin\jusched.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
 C:\WINDOWS\system32\drivers\CDAC11BA.EXE
 C:\WINDOWS\system32\cisvc.exe
 C:\WINDOWS\system32\inetsrv\inetinfo.exe
 C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 C:\WINDOWS\System32\snmp.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\mqsvc.exe
 C:\WINDOWS\system32\mqtgsvc.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
 C:\Programmi\File comuni\LogiShrd\LVCOMSER\LVComSer.exe
 C:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
 F:\RavMonE.exe
 C:\WINDOWS\System32\wbem\wmiapsrv.exe
 F:\RavMonE.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\Java\jre1.5.0_09\bin\jucheck.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\Programmi\eMule\emule.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 C:\WINDOWS\system32\cidaemon.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 C:\WINDOWS\System32\dllhost.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 F:\RavMonE.exe
 C:\Programmi\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\cmd.exe
 
 »»»»»»»»»»»»»»»»»»»»»»»» hosts
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kromix
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kromix\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Kromix\PREFER~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Programmi
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="Pagina iniziale corrente"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
 !!!Attention, following keys are not inevitably infected!!!
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 "AppInit_DLLs"=""
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
 !!!Attention, following keys are not inevitably infected!!!
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
 "System"=""
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Rustock
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» DNS
 
 Description: Scheda Fast Ethernet VIA compatibile - Miniport dell'Utilità di pianificazione pacchetti
 DNS Server Search Order: 192.168.1.1
 
 HKLM\SYSTEM\CCS\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 HKLM\SYSTEM\CS1\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 HKLM\SYSTEM\CS3\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 28 Nov 2007 18:39    Oggetto: |   |  
				| 
 |  
				| Credo che non lo abbia eliminato. Adesso collegati a BitDefender
 e procedi con la scansione online.
 Dovrai usare Internet Explorer come browser però e abbi pazienza perchè può impiegare parecchio.
 Non dimenticare di postare un nuovo log di HJT senza "tagliargli la testa".
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 30 Nov 2007 11:09    Oggetto: Ecco la nuova lista ... con la testa ... |   |  
				| 
 |  
				| di seguito la nuova scansione con hJT: 
 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 10.07.17, on 30/11/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Programmi\QuickTime\qttask.exe
 C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
 C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe
 C:\Programmi\MSN Messenger\MsnMsgr.Exe
 C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe
 C:\WINDOWS\system32\cisvc.exe
 C:\WINDOWS\system32\inetsrv\inetinfo.exe
 C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 C:\WINDOWS\System32\snmp.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\mqsvc.exe
 C:\WINDOWS\system32\mqtgsvc.exe
 C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 C:\Programmi\File comuni\Nero\Lib\NMIndexStoreSvr.exe
 C:\Programmi\File comuni\Nokia\MPAPI\MPAPI3s.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Programmi\MSN Messenger\usnsvc.exe
 F:\RavMonE.exe
 C:\WINDOWS\System32\wbem\wmiapsrv.exe
 C:\Documents and Settings\Kromix\Desktop\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar3.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [MOD] C:\Programmi\Microangelo\muamgr.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\wianmpa.exe
 O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe"
 O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\RavMonE.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO LOCALE')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &eBay Search - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O17 - HKLM\System\CS1\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\SrvLnch\SrvLnch.exe
 O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 O23 - Service: Gestione avanzate periferiche (peavge) - Unknown owner - C:\WINDOWS\Downlo~1\gznjr4\2g758h2.exe (file missing)
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: wampapache - Apache Software Foundation - c:\wamp\Apache2\bin\Apache.exe
 O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
 O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programmi\Windows Live\installer\WLSetupSvc.exe
 
 --
 End of file - 7539 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 30 Nov 2007 11:18    Oggetto: |   |  
				| 
 |  
				| Hai fatto girare bitdefender? 
 Il ravmon c'è ancora... ma smitfraudfix l'hai fatto girare da modalità provvisoria o dalla modalità normale?.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 30 Nov 2007 11:56    Oggetto: re |   |  
				| 
 |  
				| l'ho fatto girare in modalita normale ... mannaggia .. 
 devo rifarlo in modalita provissoria ? vero?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 30 Nov 2007 11:58    Oggetto: si si il bit defender |   |  
				| 
 |  
				| si si il bit difender l'ho usato.... |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 30 Nov 2007 12:49    Oggetto: Re: si si il bit defender |   |  
				| 
 |  
				|  	  | kromixcts ha scritto: |  	  | si si il bit difender l'ho usato.... | 
 E non ti ha trovato niente? Hai memorizzato il log?
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Smjert Dio maturo
 
  
  
 Registrato: 01/04/06 18:19
 Messaggi: 1619
 Residenza: Perso nella rete
 
 | 
			
				|  Inviato: 30 Nov 2007 14:10    Oggetto: Re: re |   |  
				| 
 |  
				|  	  | kromixcts ha scritto: |  	  | l'ho fatto girare in modalita normale ... mannaggia .. 
 devo rifarlo in modalita provissoria ? vero?
 | 
 
 eh sì.. il file era in uso e non è riuscito a cancellarlo.
 Sulla guida c'era scritto, comunque niente di grave, basta rifarlo ^^
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| kromixcts Mortale devoto
 
  
 
 Registrato: 28/11/07 11:34
 Messaggi: 6
 
 
 | 
			
				|  Inviato: 04 Dic 2007 14:21    Oggetto: ecco qua 2 scansioni in modalita provvisoria |   |  
				| 
 |  
				| ecco qua 2 scansioni in modalita provvisoria 
 
 »»»»»»»»»»»»»»»»»»»»»»»» ......................................................
 SmitFraudFix v2.256
 
 Scan done at 13.16.52,06, 04/12/2007
 Run from C:\Documents and Settings\Kromix\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Versione 5.1.2600] - Windows_NT
 The filesystem type is NTFS
 Fix run in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Process
 
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\cmd.exe
 
 »»»»»»»»»»»»»»»»»»»»»»»» hosts
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kromix
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kromix\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Kromix\PREFER~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Programmi
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="Pagina iniziale corrente"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
 !!!Attention, following keys are not inevitably infected!!!
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 "AppInit_DLLs"=""
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
 !!!Attention, following keys are not inevitably infected!!!
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
 "System"=""
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Rustock
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» DNS
 
 HKLM\SYSTEM\CCS\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 HKLM\SYSTEM\CS1\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 HKLM\SYSTEM\CS3\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer=192.168.1.1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» ......................................................
 
 
 
 
 
 
 
 
 ecco la seconda scansione con HijackThis v2.0.0
 
 
 
 
 
 
 
 
 Logfile of Trend Micro HijackThis v2.0.0 (BETA)
 Scan saved at 13.15.36, on 04/12/2007
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 Boot mode: Safe mode
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Documents and Settings\Kromix\Desktop\HiJackThis_v2.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar3.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
 O4 - HKLM\..\Run: [MOD] C:\Programmi\Microangelo\muamgr.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exe
 O4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
 O4 - HKLM\..\Run: [WinampAgent] C:\Programmi\Winamp\wianmpa.exe
 O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmi\File comuni\LogiShrd\LComMgr\Communications_Helper.exe"
 O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\RavMonE.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [swg] C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Nero\Lib\NMBgMonitor.exe"
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIZIO DI RETE')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Programmi\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &eBay Search - res://C:\Programmi\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
 O8 - Extra context menu item: Download &Flash Movies - C:\Programmi\Flash2X\Flash Hunter\save.htm
 O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.5.0_09\bin\ssv.dll
 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
 O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
 O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C:\Programmi\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O17 - HKLM\System\CS1\Services\Tcpip\..\{3C7FDC8E-E588-4A9D-BCCC-1219596E8FBC}: NameServer = 192.168.1.1
 O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
 O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\LVMVFM\LVPrcSrv.exe
 O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmi\File comuni\LogiShrd\SrvLnch\SrvLnch.exe
 O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe
 O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exe
 O23 - Service: Gestione avanzate periferiche (peavge) - Unknown owner - C:\WINDOWS\Downlo~1\gznjr4\2g758h2.exe (file missing)
 O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
 O23 - Service: wampapache - Apache Software Foundation - c:\wamp\Apache2\bin\Apache.exe
 O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
 O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Programmi\Windows Live\installer\WLSetupSvc.exe
 
 --
 End of file - 6371 bytes
 |  | 
	
		| Top |  | 
	
		|  | 
	
		| Sante62 Dio maturo
 
  
  
 Registrato: 27/06/07 17:55
 Messaggi: 3477
 Residenza: Floridia
 
 | 
			
				|  Inviato: 04 Dic 2007 18:55    Oggetto: |   |  
				| 
 |  
				| Sarò qualcosa di insidioso... Ha trovato qualcosa ma non l'ha eliminata
   Guarda questa discussione riguardante Systemscan di SuspectFile, scaricalo e fai la scansione postando il risultato come indicato. Attenzione a esguire per bene tutti i passaggi.
 |  | 
	
		| Top |  | 
	
		|  | 
	
		|  |